arXiv:2506.01625cs.LGcs.AI2025-06NeurIPS被引 1

在对抗干扰下确保性能达标,提出更稳健的高斯过程优化方法

Robust Satisficing Gaussian Process Bandits Under Adversarial Attacks

  • 采用满足性目标替代最坏情况优化,聚焦稳定达成预设性能阈值
  • 两种算法分别实现亚线性后悔率与扰动幅度相关后悔界,适应不同攻击模式
  • 实验表明在不确定对抗环境下优于传统方法,尤其当模型设定有误时

我们研究在未知且可能变化的对抗扰动下高斯过程(GP)优化问题。不同于传统鲁棒优化聚焦最坏情况下的最大性能,本文提出一种鲁棒满足性目标:在对抗条件下仍能持续达到预设性能阈值τ。我们提出两种基于不同鲁棒满足性形式的新算法,并证明它们属于统一的鲁棒满足性框架。进一步地,每种算法在不同敌手假设下提供不同保证:一种在特定条件下实现随时间亚线性后悔;另一种不依赖敌手假设,但后悔界与扰动幅度相关。大量实验表明,本方法在实现满足性目标方面优于现有鲁棒优化方法,尤其当鲁棒优化框架中的模糊集设定不准确时。

原文摘要 · Abstract (English)

We address the problem of Gaussian Process (GP) optimization in the presence of unknown and potentially varying adversarial perturbations. Unlike traditional robust optimization approaches that focus on maximizing performance under worst-case scenarios, we consider a robust satisficing objective, where the goal is to consistently achieve a predefined performance threshold $τ$, even under adversarial conditions. We propose two novel algorithms based on distinct formulations of robust satisficing, and show that they are instances of a general robust satisficing framework. Further, each algorithm offers different guarantees depending on the nature of the adversary. Specifically, we derive two regret bounds: one that is sublinear over time, assuming certain conditions on the adversary and the satisficing threshold $τ$, and another that scales with the perturbation magnitude but requires no assumptions on the adversary. Through extensive experiments, we demonstrate that our approach outperforms the established robust optimization methods in achieving the satisficing objective, particularly when the ambiguity set of the robust optimization framework is inaccurately specified.

高斯过程对抗鲁棒优化算法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。